Linux kernel CVE announcements
 help / color / mirror / Atom feed
- recent:[subjects (threaded)|topics (new)|topics (active)]
2026-08-15  6:12 CVE-2026-74439: iommu/vt-d: Clear Present bit before tearing down scalable-mode context entry
2026-08-15  6:12 CVE-2026-74438: crypto: sun4i-ss - Remove insecure and unused rng_alg
2026-08-15  6:12 CVE-2026-74437: media: uvcvideo: Fix deadlock if uvc_status_stop is called from async_ctrl.work
2026-08-15  6:12 CVE-2026-74436: rxrpc: serialize kernel accept preallocation with socket teardown
2026-08-15  6:12 CVE-2026-74435: rxrpc: rxrpc_verify_data ensure rx_dec_buffer alloc
2026-08-15  6:12 CVE-2026-74434: rxrpc: Don't move a peeked OOB message onto the pending queue
2026-08-15  6:12 CVE-2026-74433: rxrpc: Fix UAF in rxgk_issue_challenge()
2026-08-15  6:12 CVE-2026-74432: rxrpc: Fix leak of released call in recvmsg(MSG_PEEK)
2026-08-15  6:12 CVE-2026-74431: rxrpc: Fix potential infinite loop in rxrpc_recvmsg()
2026-08-15  6:12 CVE-2026-74430: rxrpc: Fix ACKALL packet handling
2026-08-15  6:12 CVE-2026-74429: rxrpc: Fix the reception of a reply packet before data transmission
2026-08-15  6:12 CVE-2026-74428: rxrpc: Fix double unlock in rxrpc_recvmsg()
2026-08-15  6:12 CVE-2026-74427: afs: Fix netns teardown to cancel the preallocation charger
2026-08-15  6:12 CVE-2026-74426: afs: fix NULL pointer dereference in afs_get_tree()
2026-08-15  6:12 CVE-2026-74425: afs: handle CB.InitCallBackState3 requests without a server record
2026-08-15  6:12 CVE-2026-74424: fbcon: fix NULL pointer dereference for a console without vc_data
2026-08-15  6:12 CVE-2026-74423: accel/amdxdna: Fix leak when pinning ubuf pages
2026-08-15  6:12 CVE-2026-74422: drm/rockchip: inno-hdmi: Switch to drmm_kzalloc()
2026-08-15  6:12 CVE-2026-74421: drm/rockchip: dw_dp: Switch to drmm_kzalloc()
2026-08-15  6:12 CVE-2026-74420: drm/gpusvm: Reject VMAs with VM_IO or VM_PFNMAP when creating SVM ranges
2026-08-15  6:12 CVE-2026-74419: accel/amdxdna: Adjust size for copy_to_user()
2026-08-15  6:12 CVE-2026-74418: dma-fence: Fix potential tracepoint null pointer dereferences
2026-08-15  6:12 CVE-2026-74417: drm/radeon: fix integer overflow in radeon_align_pitch()
2026-08-15  6:12 CVE-2026-74416: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure
2026-08-15  6:12 CVE-2026-74415: spi: atcspi200: fix use-after-free when driver unbind
2026-08-15  6:12 CVE-2026-74414: hfsplus: Remove the duplicate attr inode dirty marking action
2026-08-15  6:12 CVE-2026-74413: wifi: rtw89: fix wrong pci_get_drvdata type in AER handlers
2026-08-15  6:12 CVE-2026-74412: wifi: rtw88: fix wrong pci_get_drvdata type in AER handlers
2026-08-15  6:12 CVE-2026-74411: wifi: rtw89: Correct data type for scan index to avoid infinite loop
2026-08-15  6:12 CVE-2026-74410: wifi: rtw88: fix OOB read from firmware RX descriptor exceeding DMA buffer
2026-08-15  6:12 CVE-2026-74409: wifi: rtw89: add bounds check on firmware mac_id in link lookup
2026-08-15  6:12 CVE-2026-74408: wifi: ath9k: fix OOB access from firmware tx status queue ID
2026-08-15  6:12 CVE-2026-74407: wifi: ath11k: cancel SSR work items during PCI shutdown
2026-08-15  6:12 CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive().
2026-08-15  6:12 CVE-2026-74405: OPP: Fix race between OPP addition and lookup
2026-08-15  6:12 CVE-2026-74404: crypto: ccp - Fix snp_filter_reserved_mem_regions() off-by-one
2026-08-15  6:12 CVE-2026-74403: crypto: ccp - Check for page allocation failure correctly in TIO
2026-08-15  6:12 CVE-2026-74402: crypto: atmel-sha204a - fix blocking and non-blocking rng logic
2026-08-15  6:12 CVE-2026-74401: dlm: fix add msg handle in send_queue ordered
2026-08-15  6:12 CVE-2026-74400: bpf: fix crash in bpf_[set|remove]_dentry_xattr for negative dentries
2026-08-15  6:12 CVE-2026-74399: evm: terminate and bound the evm_xattrs read buffer
2026-08-15  6:12 CVE-2026-74398: ipv6: addrconf: bail out of dad_failure when state is no longer POSTDAD
2026-08-15  6:12 CVE-2026-74397: IB/mlx5: Fix transport-domain rollback and initialize lb mutex earlier
2026-08-15  6:12 CVE-2026-74396: RDMA/mlx5: Fix UMR XLT cleanup on ODP populate failure
2026-08-15  6:12 CVE-2026-74395: RDMA/mlx5: Fix devx subscribe-event unwind NULL dereference
2026-08-15  6:12 CVE-2026-74394: RDMA/srpt: fix integer overflow in immediate data length check
2026-08-15  6:12 CVE-2026-74393: drm/syncobj: Fix memory leak in drm_syncobj_find_fence()
2026-08-15  6:11 CVE-2026-74392: dm: limit target bio polling to one shot
2026-08-15  6:11 CVE-2026-74391: tracing: Bound synthetic-field strings with seq_buf
2026-08-15  6:11 CVE-2026-74390: RDMA/irdma: Fix out-of-bounds write in irdma_copy_user_pgaddrs
2026-08-15  6:11 CVE-2026-74389: RDMA/hns: Fix log flood after cmd_mbox failure
2026-08-15  6:11 CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data
2026-08-15  6:11 CVE-2026-74387: ALSA: seq: midi: Serialize output teardown with event_input
2026-08-15  6:11 CVE-2026-74386: nvmet-tcp: fix page fragment cache leak in error path
2026-08-15  6:11 CVE-2026-74385: nvmet-tcp: check return value of nvmet_tcp_set_queue_sock
2026-08-15  6:11 CVE-2026-74384: nvme-multipath: fix flex array size in struct nvme_ns_head
2026-08-15  6:11 CVE-2026-74383: nvme-pci: fix out-of-bounds access in nvme_setup_descriptor_pools
2026-08-15  6:11 CVE-2026-74382: net/sched: cls_bpf: prevent unbounded recursion in offload rollback
2026-08-15  6:11 CVE-2026-74381: gpu: host1x: Allow entries in BO caches to be freed
2026-08-15  6:11 CVE-2026-74380: gpu: host1x: Fix iommu_map_sgtable() return value check
2026-08-15  6:11 CVE-2026-74379: dax/kmem: account for partial discontiguous resource upon removal
2026-08-15  6:11 CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe
2026-08-15  6:11 CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path
2026-08-15  6:11 CVE-2026-74376: md/raid10: reset read_slot when reusing r10bio for discard
2026-08-15  6:11 CVE-2026-74375: md/raid1,raid10: fix deadlock in read error recovery path
2026-08-15  6:11 CVE-2026-74374: md/raid1,raid10: fix error-path detection with md_cloned_bio()
2026-08-15  6:11 CVE-2026-74373: md/raid1,raid10: fix bio accounting for split md cloned bios
2026-08-15  6:11 CVE-2026-74372: raid1: fix nr_pending leak in REQ_ATOMIC bad-block error path
2026-08-15  6:11 CVE-2026-74371: bpf: fix BPF_PROG_QUERY OOB write and cgroup backward compat
2026-08-15  6:11 CVE-2026-74370: liveupdate: fix TOCTOU race in luo_session_retrieve()
2026-08-15  6:11 CVE-2026-74369: liveupdate: fix u-a-f in luo_file_unpreserve_files() and luo_file_finish()
2026-08-15  6:11 CVE-2026-74368: wifi: ath12k: fix memory leak in ath12k_wifi7_dp_rx_h_verify_tkip_mic()
2026-08-15  6:11 CVE-2026-74367: wifi: ath12k: fix inconsistent arvif state in vdev_create error paths
2026-08-15  6:11 CVE-2026-74366: wifi: ath12k: fix NULL deref in change_sta_links for unready link
2026-08-15  6:11 CVE-2026-74365: nvdimm/btt: Handle preemption in BTT lane acquisition
2026-08-15  6:11 CVE-2026-74364: bpf: Reject exclusive maps as inner maps in map-in-map
2026-08-15  6:11 CVE-2026-74363: bpf: fix UAF by restoring RCU-delayed inode freeing in bpffs
2026-08-15  6:11 CVE-2026-74362: ext2: fix ignored return value of generic_write_sync()
2026-08-15  6:11 CVE-2026-74361: nvme: fix FDP fdpcidx bounds check
2026-08-15  6:11 CVE-2026-74360: bpf: Reject exclusive maps for bpf_map_elem iterators
2026-08-15  6:11 CVE-2026-74359: configfs_lookup(): don't leave ->s_dentry dangling on failure
2026-08-15  6:11 CVE-2026-74358: ext4: fix fast commit wait/wake bit mapping on 64-bit
2026-08-15  6:11 CVE-2026-74357: drm/amdgpu: fix KASAN slab-out-of-bounds in amdgpu_coredump ring dump
2026-08-15  6:11 CVE-2026-74356: vhost: fix vhost_get_avail_idx for a non empty ring
2026-08-15  6:11 CVE-2026-74355: iommu/vt-d: Fix RB-tree corruption in probe error path
2026-08-15  6:11 CVE-2026-74354: bpf: Take mmap_lock in zap_pages()
2026-08-15  6:11 CVE-2026-74353: drm/amdkfd: always resume_all after suspend_all
2026-08-15  6:11 CVE-2026-74352: of: reserved_mem: avoid post-init UAF when alloc_reserved_mem_array() fails
2026-08-15  6:11 CVE-2026-74351: ocfs2: rebase copied fsdlm LVB pointers in locking_state
2026-08-15  6:11 CVE-2026-74350: ocfs2: validate fast symlink target during inode read
2026-08-15  6:11 CVE-2026-74349: ocfs2: reject FITRIM ranges shorter than a cluster
2026-08-15  6:11 CVE-2026-74348: ocfs2/dlm: require a ref for locking_state debugfs open
2026-08-15  6:11 CVE-2026-74347: netfilter: cttimeout: detach dataplane timeout policy and repurpose refcount
2026-08-15  6:11 CVE-2026-74346: RDMA/irdma: Fix OOB read during CQ MR registration
2026-08-15  6:11 CVE-2026-74345: RDMA/siw: Fix endpoint/socket association handling
2026-08-15  6:11 CVE-2026-74344: bpf: Clear rb node linkage when freeing bpf_rb_root
2026-08-15  6:11 CVE-2026-74343: kernfs: fix xattr race condition with multiple superblocks
2026-08-15  6:11 CVE-2026-74342: kernfs: link kn to its parent before the LSM init hook
2026-08-15  6:11 CVE-2026-74341: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response
2026-08-15  6:11 CVE-2026-74340: wifi: wcn36xx: fix OOB read from firmware count in PRINT_REG_INFO indication
2026-08-15  6:11 CVE-2026-74339: ALSA: seq: Clear variable event pointer on read
2026-08-15  6:11 CVE-2026-74338: bpf: Reject sleepable BPF_LSM_CGROUP programs at load time
2026-08-15  6:11 CVE-2026-74337: bpf: Fix NMI/tracepoint re-entry deadlock on lru locks
2026-08-15  6:11 CVE-2026-74336: wifi: mac80211: bound S1G TIM PVB walk to the TIM element
2026-08-15  6:11 CVE-2026-74335: bpf: Fix NULL pointer dereference in bpf_task_from_vpid()
2026-08-15  6:11 CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd
2026-08-15  6:11 CVE-2026-74333: ASoC: amd: acp-sdw-legacy: Bound DAI link iteration
2026-08-15  6:10 CVE-2026-74332: ASoC: amd: acp-sdw-sof: Bound DAI link iteration
2026-08-15  6:10 CVE-2026-74331: firmware_loader: Fix recursive lock in device_cache_fw_images()
2026-08-15  6:10 CVE-2026-74330: configfs: fix lockless traversals of ->s_children
2026-08-15  6:10 CVE-2026-74329: watchdog: unregister PM notifier on watchdog unregister
2026-08-15  6:10 CVE-2026-74328: iommufd: Destroy the pages content after detaching from dmabuf
2026-08-15  6:10 CVE-2026-74327: vmalloc: fix NULL pointer dereference in is_vm_area_hugepages()
2026-08-15  6:10 CVE-2026-74326: wifi: mt76: mt7921: fix resource leak in probe error path
2026-08-15  6:10 CVE-2026-74325: wifi: mt76: use kfree_rcu for offchannel link in mt76_put_vif_phy_link
2026-08-15  6:10 CVE-2026-74324: wifi: mt76: mt7925: validate skb length in testmode query
2026-08-15  6:10 CVE-2026-74323: wifi: mt76: mt7996: Fix possible token leak in mt7996_tx_prepare_skb()
2026-08-15  6:10 CVE-2026-74322: wifi: mt76: mt7996: Fix possible NULL pointer dereference in mt7996_mac_write_txwi_80211()
2026-08-15  6:10 CVE-2026-74321: btrfs: fix invalid pointer dereference in __btrfs_run_delayed_refs()
2026-08-15  6:10 CVE-2026-74320: fbdev: sm501fb: Fix buffer errors in OF binding code
2026-08-15  6:10 CVE-2026-74319: btrfs: zoned: fix deadlock waiting for ticket during data relocation
2026-08-15  6:10 CVE-2026-74318: btrfs: fix deadlock cloning inline extent when using flushoncommit
2026-08-15  6:10 CVE-2026-74317: ixgbe: do not configure xps for XDP queues
2026-08-15  6:10 CVE-2026-74316: NFSD: Handle layout stid in nfsd4_drop_revoked_stid()
2026-08-15  6:10 CVE-2026-74315: lockd: Avoid hashing uninitialized bytes in nlm4svc_lookup_file()
2026-08-15  6:10 CVE-2026-74314: bpf: Cancel special fields on map value recycle
2026-08-15  6:10 CVE-2026-74313: vduse: hold vduse_lock across IDR lookup in open path
2026-08-15  6:10 CVE-2026-74312: vhost/vdpa: validate virtqueue index in mmap and fault paths
2026-08-15  6:10 CVE-2026-74311: virtio: rtc: tear down old virtqueues before restore
2026-08-15  6:10 CVE-2026-74310: vhost/net: complete zerocopy ubufs only once
2026-08-15  6:10 CVE-2026-74309: vdpa/octeon_ep: fix IRQ-to-ring mapping in interrupt handler
2026-08-15  6:10 CVE-2026-74308: ext4: fix kernel BUG in ext4_write_inline_data_end
2026-08-15  6:10 CVE-2026-74307: ext4: validate donor file superblock early in EXT4_IOC_MOVE_EXT
2026-08-15  6:10 CVE-2026-74306: vfio/qat: fix f_pos race in qat_vf_resume_write()
2026-08-15  6:10 CVE-2026-74305: bpf: Tighten cgroup storage cookie checks for prog arrays
2026-08-15  6:10 CVE-2026-74304: Bluetooth: hci_qca: fix NULL pointer dereference in qca_setup() for non-serdev device
2026-08-15  6:10 CVE-2026-74303: Bluetooth: hci_qca: fix NULL pointer dereference in qca_dmp_hdr() for non-serdev device
2026-08-15  6:10 CVE-2026-74302: Bluetooth: hci_core: Fix UAF in hci_unregister_dev()
2026-08-15  6:10 CVE-2026-74301: Bluetooth: btmtk: fix URB leak in alloc_mtk_intr_urb error path
2026-08-15  6:10 CVE-2026-74300: Bluetooth: hci: validate codec capability element length
2026-08-15  6:10 CVE-2026-74299: RDMA/core: Fix FRMR aging push to queue error flow
2026-08-15  6:10 CVE-2026-74298: RDMA/core: Fix FRMR set pinned push error path
2026-08-15  6:10 CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size
2026-08-15  6:10 CVE-2026-74296: RDMA/mlx5: Release the HW‑provided UAR index rather than the SW one
2026-08-15  6:10 CVE-2026-74295: ASoC: codecs: hdac_hdmi: Validate written enum value
2026-08-15  6:10 CVE-2026-74294: ASoC: meson: aiu: Validate written enum values
2026-08-15  6:10 CVE-2026-74293: ASoC: fsl: fsl_audmix: Validate written enum values
2026-08-15  6:10 CVE-2026-74292: ASoC: tegra: tegra210_ahub: Validate written enum value
2026-08-15  6:10 CVE-2026-74291: ASoC: topology: Check PCM and DAI name strings before use
2026-08-15  6:10 CVE-2026-74290: net/sched: cls_flow: Dont expose folded kernel pointers
2026-08-15  6:10 CVE-2026-74289: ipv4: fib: Don't dump dying fib_info in fib_leaf_notify().
2026-08-15  6:10 CVE-2026-74288: net: fib_rules: Don't dump dying fib_rule in fib_rules_dump().
2026-08-15  6:10 CVE-2026-74287: sctp: validate embedded address parameter length
2026-08-15  6:10 CVE-2026-74286: net: pfcp: allocate per-cpu tstats for PFCP netdevs
2026-08-15  6:10 CVE-2026-74285: net: Stop leased rxq before uninstalling its memory provider
2026-08-15  6:10 CVE-2026-74284: net/sched: sch_hfsc: Don't make class passive twice
2026-08-15  6:10 CVE-2026-74283: tipc: require net admin for TIPCv2 netlink mutators
2026-08-15  6:10 CVE-2026-74282: tipc: prevent snt_unacked underflow on CONN_ACK
2026-08-15  6:10 CVE-2026-74281: tipc: reject inverted service ranges from peer bindings
2026-08-15  6:10 CVE-2026-74280: crypto: marvell/octeontx - fix DMA cleanup using wrong loop index
2026-08-15  6:10 CVE-2026-74279: crypto: cavium/cpt - fix DMA cleanup using wrong loop index
2026-08-15  6:10 CVE-2026-74278: ALSA: seq: Fix kernel heap address leak in bounce_error_event()
2026-08-15  6:10 CVE-2026-74277: iommu/dma-iommu: Fix wrong scatterlist length assignment in P2PDMA path
2026-08-15  6:10 CVE-2026-74276: spi: xilinx: use FIFO occupancy register to determine buffer size
2026-08-15  6:10 CVE-2026-74275: cxl/region: Fix out-of-bounds access in cxl_cancel_auto_attach()
2026-08-15  6:10 CVE-2026-74274: cxl/region: Fill first free targets[] slot during auto-discovery
2026-08-15  6:10 CVE-2026-74273: cxl/region: Block region delete during region creation
2026-08-15  6:09 CVE-2026-74272: cxl/region: Resolve region deletion races
2026-08-15  6:09 CVE-2026-74271: power: supply: core: fix supplied_from allocations
2026-08-15  6:09 CVE-2026-74270: handshake: Require admin permission for DONE command
2026-08-15  6:09 CVE-2026-74269: bnxt: fix head underflow on XDP head-grow
2026-08-15  6:09 CVE-2026-74268: tcp: clear sock_ops cb flags before force-closing a child socket
2026-08-15  6:09 CVE-2026-74267: net/sched: sch_codel: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
2026-08-15  6:09 CVE-2026-74266: net/sched: sch_dualpi2: Do not call qdisc_tree_reduce_backlog during peek before restoring qlen
2026-08-15  6:09 CVE-2026-74265: net: mana: initialize gdma queue id to INVALID_QUEUE_ID
2026-08-15  6:09 CVE-2026-74264: net: watchdog: fix refcount tracking races
2026-08-15  6:09 CVE-2026-74263: net: wwan: t7xx: check skb_clone in control TX
2026-08-15  6:09 CVE-2026-74262: kcm: use WRITE_ONCE() when changing lower socket callbacks
2026-08-15  6:09 CVE-2026-74261: ALSA: seq: avoid stale FIFO cells during resize
2026-08-15  6:09 CVE-2026-74260: netfilter: nf_dup_netdev: add nf_dev_xmit_recursion*() helpers and use them
2026-08-15  6:09 CVE-2026-74259: cifs: remove all cifs files before kill super
2026-08-15  6:09 CVE-2026-74258: bpf: Guard __get_user acesss with access_ok for uprobe_multi data
2026-08-15  6:09 CVE-2026-74257: sockmap: Fix use-after-free in udp_bpf_recvmsg()
2026-08-15  6:09 CVE-2026-74256: bpf, sockmap: fix integer overflow in bpf_msg_pop_data() bounds check
2026-08-15  6:09 CVE-2026-74255: tipc: fix UAF in tipc_l2_send_msg()
2026-08-15  6:09 CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF)
2026-08-15  6:09 CVE-2026-72501: RDMA/bnxt_re: Initialize dpi variable to zero
2026-08-15  6:09 CVE-2026-72500: RDMA/bnxt_re: Free SRQ toggle page after firmware teardown
2026-08-15  6:09 CVE-2026-72499: RDMA/bnxt_re: Free CQ toggle page after firmware teardown
2026-08-15  6:09 CVE-2026-72498: RDMA/bnxt_re: Avoid displaying the kernel pointer
2026-08-15  6:09 CVE-2026-72497: RDMA/bnxt_re: Add a max slot check for SQ
2026-08-15  6:09 CVE-2026-72496: RDMA/bnxt_re: Proper rollback if the ioremap fails
2026-08-15  6:09 CVE-2026-72495: RDMA/bnxt_re: Avoid repeated requests to allocate WC pages
2026-08-15  6:09 CVE-2026-72464: xprtrdma: Repost Receive buffers for malformed replies
2026-08-15  6:09 CVE-2026-72463: xfrm: Fix dev use-after-free in xfrm async resumption
2026-08-15  6:09 CVE-2026-72462: apparmor: fix race in unix socket mediation when peer_path is used
2026-08-15  6:09 CVE-2026-72461: apparmor: fix refcount leak when updating the sk_ctx
2026-08-15  6:08 CVE-2026-72460: apparmor: check label build before no_new_privs test
2026-08-15  6:08 CVE-2026-72459: apparmor: aa_label_alloc use aa_label_free on alloc failure
2026-08-15  6:08 CVE-2026-72455: apparmor: fix uninitialised pointer passed to audit_log_untrustedstring()

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox